JFrog Artifactory flaw can hand out admin access
JFrog Artifactory, a tool companies use to store and manage their software packages, has a login weakness. In its default setup, someone with network access can reach it without a password and gain full administrator control.
- Severity
- CriticalCVSS 3.1 · 9.8
- Fix
- Update availableFix recorded on Sep 2, 2026
- Affected versions
- before 7.111.21; 7.117.0 to before 7.117.28; 7.125.0 to before 7.125.20+3 more
- Weakness
- CWE-287Improper Authentication
- Exploit likelihood
- 7.7% in 30 daysEPSS, higher than 94% of known flaws
- Affects
- Artifactory
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Sep 2, 2026
- Federal fix deadline
- Sep 5, 2026
What to do
There is no published affected or fixed version number yet, so check the JFrog Artifactory admin console and the official JFrog security advisories page for a version-specific fix.
Until JFrog publishes a version-specific patch, restrict network access to the Artifactory admin interface so it is not reachable from untrusted networks, and review its authentication configuration for anything left at default.
Technical details
CVE-2026-82329 (CVSS 9.8, critical) describes an improper authentication weakness (CWE-287) in JFrog Artifactory. Under default configuration, an unauthenticated attacker with network access to the instance may be able to obtain administrative privileges. NVD has not yet published affected or fixed version ranges, and no vendor advisory, proof-of-concept, or technical write-up was found beyond the NVD record itself.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- docs.jfrog.com · artifactory-self-managed-releases (docs) patch release notes Release Notes
- docs.jfrog.com · jfrog-security-advisories (docs) patch release notes Vendor Advisory
- nvd.nist.gov · CVE-2026-82329 us government resource vdb entry
- tenable.com · CVE-2026-82329 third party advisory vdb entry
- cvefeed.io · CVE-2026-82329 third party advisory vdb entry
- cisa.gov · known-exploited-vulnerabilities-catalog NVD CCCS Canada Third Party Advisory US Government Resource
- securityonline.info · cve-2026-82329-exploited-admin-privileges SecurityOnline
- securityonline.info · cosmos-evm-balance-error-multichain-heist SecurityOnline
- securityonline.info · nightmareeclipse-pocs-avast-kaspersky-nvidia SecurityOnline
- securityweek.com · critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild SecurityWeek
- gbhackers.com · critical-jfrog-artifactory-authentication-bypass-exploited GBHackers
- cybersecuritynews.com · jfrog-artifactory-auth-bypass-exploited Cyber Security News
- any.run · threat-intelligence-lookup Cyber Security News
- thehackernews.com · attackers-exploit-critical-jfrog.html TheHackerNews
- darkreading.com · attackers-pounce-critical-artifactory-flaw-disclosure DarkReading
- bleepingcomputer.com · hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens BleepingComputer
- socradar.io · jfrog-artifactory-cve-2026-82329 SOCRadar
- cisa.gov · cisa-adds-seven-known-exploited-vulnerabilities-catalog SOCRadar